OFAC & Export-Control Screening: A Plain-English Guide
There's a whole category of business relationship that can quietly turn a routine sale into a federal enforcement matter, and the maddening part is you usually can't spot it by looking. A new customer, a supplier, a joint-venture partner — before any money moves, you generally need to confirm they aren't on a U.S. government restricted-party list. And "we had no idea" isn't much of a shield here: much of U.S. sanctions law is strict liability, so the penalty can land even when the violation was completely inadvertent. This is the plain-English version — which lists matter, and how to actually screen a name.
The three agencies
Three agencies keep the lists that matter most, and to make life harder, they overlap. Here's who does what.
Treasury — OFAC (sanctions)
- SDN List (Specially Designated Nationals): the strictest. U.S. persons are generally prohibited from any dealings with an SDN, and any assets it holds in U.S. jurisdiction must be frozen (blocked).
- Consolidated (non-SDN) lists: narrower, menu-based restrictions — for example the Sectoral Sanctions (SSI) list limits certain debt/equity dealings rather than imposing a full freeze.
Commerce — BIS (export control)
- Entity List: a license is required to export most items to the party, often with a presumption of denial.
- Denied Persons List (DPL): the party's export privileges have been revoked; U.S. persons generally can't participate in any export with them.
- Unverified List (UVL): BIS couldn't verify the party — a red flag requiring extra due diligence, and license exceptions are unavailable.
- Military End-User (MEU) List: a license is required for listed items over military end-use concerns.
State — DDTC (defense trade)
- ITAR Debarred Parties: barred under the Arms Export Control Act from participating in defense-article or defense-service exports.
How to actually screen a name
The lists are the easy part. Screening well is mostly about not tricking yourself — here's the workflow that holds up.
- Start with the real legal name, then widen it. Run the registered name plus the aliases and variants a party actually uses. The bad guys rarely trade under the name on the list.
- Let the match be fuzzy. These lists are full of transliterations and spelling variants — "Mohammed" versus "Muhammad," half a dozen ways to romanize the same Cyrillic name. If you only accept exact matches, you'll sail right past real hits.
- Treat every hit as a maybe. A name match is a question, not an answer. Before you act on it, confirm you've got the right party using an address, a date of birth, a registration number — something on the official record that pins down identity. Plenty of innocent people share a name with someone on a list.
- Follow the ownership. Screening the counterparty isn't enough; its owners and officers count too. OFAC's "50 percent rule" means a company owned 50% or more by sanctioned parties is itself blocked, even when it never appears on any list by name.
- Write it down, and do it again later. Keep an auditable record of what you screened and when — and re-screen, because these lists change constantly. A party that was clean in January can be designated in March.
One catch: screening isn't the whole job
Clearing a party against the lists is necessary, but on the export side it's only half the picture. Whether you actually need a license also turns on what you're shipping (its ECCN under the Commerce Control List, or the U.S. Munitions List if it's a defense article), where it's headed (the EAR Country Chart), and how it'll be used. Those are product-classification questions, and they're a separate exercise from checking a name.
A last, obvious point worth making anyway: this is general information, not legal advice. When there's a specific transaction and real money at stake, get a trade-compliance lawyer involved.